Realized last Tuesday my whole API key habit was basically leaving my front door unlocked
Last Tuesday I was doing a code review at my kitchen table in Sacramento and noticed something weird in a config file. One of our services had the production Stripe key sitting right there in plain text, and it had been like that since we set up the service maybe 14 months ago. I pulled up our git history and found the key got committed back in March of the year before and nobody caught it, not in three rounds of reviews, not in any of our deploys. Then I looked at how we handle keys everywhere else and it was the same story, keys baked into env files, shared over Slack DMs, copied into random test scripts. What got me was realizing how many people could have grabbed that key at any point and we would have had zero idea it happened, because we had no logging on it and no idea what a normal request even looks like. We spent that Friday rotating everything and setting up scoped keys, and honestly the scoping part took like 2 hours total. My question is how do you all catch this stuff before it sits there for a year, do you run some scanner in CI or is it just manual eyeballs?